MEDIUM
Plastic Labs
CVE published 2026-10-11
CVE-2026-108711
CVE-2026-108711 is a medium-severity vulnerability in Plastic Labs Honcho through version 3.3.0, allowing peer- or session-scoped API key holders to read workspace data via the POST /v3/workspaces endpoint. This issue arises from the get_or_create_workspace function only checking the workspace claim, enabling attackers to submit their parent workspace name and retrieve workspace metadata and configuration.